- Book Chapter
8
- 10.1016/b978-0-12-416688-2.00005-2
Chapter 5 - Intrusion Prevention and Detection Systems
- Jan 01, 2013
- Managing Information Security
- Christopher Day
Chapter 5 - Intrusion Prevention and Detection Systems
Intrusion detection (ID) is an important component of infrastructure protection mechanisms. Intrusion detection systems (IDSs) need to be accurate, adaptive, and extensible. Given these requirements and the complexities of today's network environments, we need a more systematic and automated IDS development process rather that the pure knowledge encoding and engineering approaches. This article describes a novel framework, MADAM ID, for Mining Audit Data for Automated Models for Instrusion Detection. This framework uses data mining algorithms to compute activity patterns from system audit data and extracts predictive features from the patterns. It then applies machine learning algorithms to the audit records taht are processed according to the feature definitions to generate intrusion detection rules. Results from the 1998 DARPA Intrusion Detection Evaluation showed that our ID model was one of the best performing of all the participating systems. We also briefly discuss our experience in converting the detection models produced by off-line data mining programs to real-time modules of existing IDSs.
Chapter 5 - Intrusion Prevention and Detection Systems
Chapter 5 - Intrusion Prevention and Detection Systems
A Review on Intrusion Detection System using Artificial Intelligence Approach
Today, intrusion detection system using the neural network is an interested and considerable area for the research community. The computational intelligence systems are defined on the basis of the following parameters: fault tolerance and adaptation; adaptable the requirements of make a better intrusion detection model. In this paper, provide an overview of the research progress using computational intelligence to the problem of intrusion detection. The goal of this paper summarized and compared research contributions of Intrusion detection system using computational intelligence and neural network, define existing research challenges and anticipated solution of machine learning. Research showed that application of machine learning techniques in intrusion detection could achieve high detection rate. Machine learning and classification algorithms help to design "Intrusion Detection Models" which can classify the network traffic into intrusive or normal traffic. This paper discusses some commonly used machine learning techniques in Intrusion Detection System and also reviews some of the existing machine learning IDS proposed by researchers at different times.
Read moreA New Model for Intrusion Detection based on Reduced Error Pruning Technique
The increasing counterfeit of the internet usage has raised concerns of the security agencies to work very hard in order to diminish the presence of the abnormal users from the web. The motive of these illicit users (called intruders) is to harm the system or the network either by gaining access to the system or prohibiting genuine users to access the resources. Hence in order to tackle the abnormalities Intrusion Detection System (IDS) with Data Mining has evolved as the most demanding approach. On the one end IDS aims to detect the intrusions by monitoring a given environment while on the other end Data Mining allows mining of these intrusions hidden among genuine users. In this regard, IDS with Data Mining has been through several revisions in consideration to meet the current requirements with efficient detection of intrusions. Also several models have been proposed for enhancing the system performance. In context to improved performance, the paper presents a new model for intrusion detection. This improved model, named as REP (Reduced Error Pruning) based Intrusion Detection Model results in higher accuracy along with the increased number of correctly classified instances.
Read moreBlockchain and federated learning-based intrusion detection approaches for edge-enabled industrial IoT networks: a survey
Blockchain and federated learning-based intrusion detection approaches for edge-enabled industrial IoT networks: a survey
Read moreIntrusion Detection Based on Active Networks
The network security is getting more important due to the wide-spread computer viruses and increasing network attacks. Nowadays, more and more security mechanisms, such as firewalls and intrusion detection systems (IDS), are introduced to protect the network from malicious attacks. This paper proposes an agent and service based intrusion detection and response system for active network. In contrast to a traditional passive network, an active network gives the nodes programmable ability to exercise various active network technologies. The intrusion response, service deployment, and service update mechanisms are centered on this technology. The proposed model of intrusion detection and response system (IDRS) catches network attacks and responses to stop the attacks at the first time to reduce the damage. Detecting, reporting, and responding capabilities are all embedded and integrated in the proposed system. A prototype system is developed using a novel data mining technology (the support vector machine) to enhance the detection function. In addition, several experiments were conducted to verify the system and results showed that the system was able to effectively identify the intrusions and respond promptly. Experiments also showed that the support vector machine outperforms the competitive neural networks in identifying the intrusions.
Read moreIntrusion detection based on Core Vector Machine and ensemble classification methods
With the widespread use of Internet, the possibilities of exposing confidential data to invaders or attackers increases. Intrusion Detection System (IDS) is used for detecting various intrusions in network environment and to prevent data from malicious attackers. In this paper, a combined algorithm based on Principal Component Analysis (PCA) and Core Vector Machine (CVM), which is an extremely fast classifier, is proposed for intrusion detection. PCA is used as feature extraction technique to select principal features from the intrusion detection KDDCup'99 dataset and an intrusion detection model is constructed by CVM algorithm. The effectiveness of the features selected is also tested on ensemble based classifiers and the results are compared with the standard classifiers.
Read moreHybrid bagging and boosting with SHAP based feature selection for enhanced predictive modeling in intrusion detection systems
The novelty and growing sophistication of cyber threats mean that high accuracy and interpretable machine learning models are needed more than ever before for Intrusion Detection and Prevention Systems. This study aims to solve this challenge by applying Explainable AI techniques, including Shapley Additive explanations feature selection, to improve model performance, robustness, and transparency. The method systematically employs different classifiers and proposes a new hybrid method called Hybrid Bagging-Boosting and Boosting on Residuals. Then, performance is taken in four steps: the multistep evaluation of hybrid ensemble learning methods for binary classification and fine-tuning of performance; feature selection using Shapley Additive explanations values retraining the hybrid model for better performance and reducing overfitting; the generalization of the proposed model for multiclass classification; and the evaluation using standard information metrics such as accuracy, precision, recall, and F1-score. Key results indicate that the proposed methods outperform state-of-the-art algorithms, achieving a peak accuracy of 98.47% and an F1 score of 96.19%. These improvements stem from advanced feature selection and resampling techniques, enhancing model accuracy and balancing precision and recall. Integrating Shapley Additive explanations-based feature selection with hybrid ensemble methods significantly boosts the predictive and explanatory power of Intrusion Detection and Prevention Systems, addressing common pitfalls in traditional cybersecurity models. This study paves the way for further research on statistical innovations to enhance Intrusion Detection and Prevention Systems performance.
Read moreDeveloping an Intelligent Intrusion Detection and Prevention System against Web Application Malware
Malware authors are continuously developing crime toolkits. This has led to the situation of zero-day attacks, where malware harm computer systems despite the protection from existing Intrusion Detection Systems (IDSs). We propose an Intelligent Intrusion Detection and Prevention System (IIDPS) approach that combines the Signature based Intrusion Detection system (SIDS), Anomaly based Intrusion Detection System (AIDS) and Response Intrusion Detection System (RIDS). We used a risk assessment approach to determine an appropriate response action against each attack event. We also demonstrated the IIDPS make the detection and prevention of malware more effective.
Read moreNeural Networks for Intrusion Detection
This paper presents Intrusion Detection Systems (IDS), Intrusion Detection and Prevention Systems (IDPS) and their classification emphasizing on the use of neural networks in IDS. Contemporary IDS usually include both signature verification and anomaly detection approaches realized by rule-based expert system and statistical module correspondingly. Neural networks may be used mainly as additional module to the statistical module to better recognize the user behavior. User behavior may be represented as frequency pattern of users command history. The paper presents an example of user profile vector for Unix-based platforms.
Read moreA Neural Network Model for Intrusion Detection Using a Game Theoretic Approach
The problem of intrusion detection in the computer networks is not new and various methodologies have been formulated to address the same. A game-theoretic representation was also formulated, using one of the oldest game playing techniques, the minimax algorithm to solve this problem. It exploited the adversary like situation between the intruder and the Intrusion Detection System (IDS) and the essence of this approach lies in the assumption that the intruder and the IDS have complete knowledge of the network and each other’s strategy. The solution for the intrusion detection problem via game theory gives the detection probability by which the IDS can detect the malicious packets on a given network when the probabilities with which the intruder sends the malicious packets on the various paths leading him to the target are known to the IDS. However, in the real world scenario, the role of the intruder and the IDS is dynamic, if the attack is detected or goes undetected the intruder tries to breach the network again with a different approach or the IDS tries to defend the network with a different strategy respectively. The next strategy for either of the two can be learnt by experience and thus, this paper, models an artificial neural network to represent this game-theoretic representation. The modeled neural network gives the detection probability of an attack by the IDS when the probabilities of sending malicious packets on the various paths leading the intruder to the target are given as an input pattern to the neural network.
Read moreDetecting Computer Network Anomaly with Data Mining Technology
With the rapid development of machine learning and Internet technology, the combination of the two methods is well appreciated recently.An anomaly and intrusion detection system is a mechanism that monitors network or system activities for malicious activities.Intrusion detection and prevention systems are primarily focused on identifying possible incidents, logging information about them and reporting attempts.As far as other usages of Intrusion detection and prevention systems are concerned, such as identifying problems with security policies and deterring individuals from violating security policies.Anomaly detection systems are becoming an important addition to the security infrastructure of nearly every organization.In this paper, we propose a novel mechanism for real-world traffic and research there cases with theoretical analysis.
Read moreA data mining framework for building intrusion detection models
There is often the need to update an installed intrusion detection system (IDS) due to new attack methods or upgraded computing environments. Since many current IDSs are constructed by manual encoding of expert knowledge, changes to IDSs are expensive and slow. We describe a data mining framework for adaptively building Intrusion Detection (ID) models. The central idea is to utilize auditing programs to extract an extensive set of features that describe each network connection or host session, and apply data mining programs to learn rules that accurately capture the behavior of intrusions and normal activities. These rules can then be used for misuse detection and anomaly detection. New detection models are incorporated into an existing IDS through a meta-learning (or co-operative learning) process, which produces a meta detection model that combines evidence from multiple models. We discuss the strengths of our data mining programs, namely, classification, meta-learning, association rules, and frequent episodes. We report on the results of applying these programs to the extensively gathered network audit data for the 1998 DARPA Intrusion Detection Evaluation Program.
Read moreSecurity in Artificial Systems
In the context of a computer system, computer security is the prevention of an illicit action against the system. For this purpose, computer security must determine the difference between normal and harmful activities. These activities can come from outside or from inside the system to be protected. In a similar manner, the role of the Human Immune System (HIS) is to detect and defend against harm. This similarity has inspired approaches in the area of computer security, including the use of immune-based approaches to build Intrusion Detection and Response Systems (IDRSs). As a concrete example, this chapter introduces a new approach for Intrusion Detection (ID) and Intrusion Response (IR) to build a completely distributed and decentralised IDRS for use in computer networks. This approach is called Intrusion Detection and Response extended with Agent Mobility, or IDReAM for short. IDReAM combines Mobile Agents (MAs) with two self-organising paradigms inspired by natural life systems. The Intrusion Detection System (IDS) is inspired by the metaphor of the immune system that protects the human body from external threats. Specialised cells of the immune system, called the T cells, travel around the body to detect possible threats by eliminating the proteins that they do not recognise as safe proteins—referred to as non-self proteins. Intrusion Detection Agents (IDAs) roam the network to detect suspicious behaviours in a manner that mimics the behaviour of T cells. The Intrusion Response System (IRS) also borrows mechanisms from the stigmergic paradigm of a colony of ants. At the time of foraging, the ants use the environment to diffuse a chemical substance called the pheromone which traces the route for the other ants from the nest to the source of food. Intrusion Response Agents (IRAs) roam the network to respond to the IDAs’ alerts, mimicking the behaviour of the ants to trace the route to the alert and give the response. The two natural systems exhibit a social behaviour by the organisation of their entities, T cells and ants, which is not possible without the functionality of mobility.KeywordsIntrusion DetectionAgent MobilityIntrusion Detection SystemComputer SecurityHuman Immune SystemThese keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.
Read moreA framework for adaptive, cost-sensitive intrusion detection and response system
Intrusion detection has been at the center of intense research in the last decade owing to the rapid increase of sophisticated attacks on computer systems. Typically, intrusion detection refers to a variety of techniques for detecting attacks in the form of malicious and unauthorized activities. There are three broad categories of detection approaches: (a) misuse-based technique that relies on pre-specified attack signatures, (b) anomaly-based approach, that typically depends on normal patterns classifying any deviation from normal as malicious; and (c) specification-based technique that although operates in a similar fashion to anomaly-based approach, employs a model of valid program behavior in a form of specifications requiring user expertise. When intrusive behavior is detected, it is desirable to take (evasive and/or corrective) actions to thwart attacks and ensure safety of the computing environment. Such countermeasures are referred to as intrusion response. Although the intrusion response component is often integrated with the Intrusion Detection System (IDS), it receives considerably less attention than IDS research owing to the inherent complexity in developing and deploying response in an automated fashion. As such, traditionally, triggering an intrusion response is left as part of the administrators responsibility, requiring a high-degree of expertise. In this work we present an integrated approach to intrusion detection and response based on the technique for monitoring abnormal patterns in the program behavior. The proposed model effectively combines the advantages of anomaly-based and specification-based approaches recognizing a known behavior through the specifications of normal and abnormal patterns and classifying unknown patterns using a machine-learning algorithm. Such combination not only allows adaptation of the specification-based detection to the new patterns, but also provides a method for automatic development of specifications. In addition to detection, our framework incorporates preemptive response. By preemption, we imply deploying response before a monitored pattern is classified completely as an intrusion. Such response deployment is likely to stop an intrusion before it can affect the system. However, preemption also inherently suffers from false positives; i.e., responses are deployed to deter correct execution which may look intrusive in its initial phase. To reduce false positives, we have developed a multi-phase response selection and deployment mechanism based on the evaluation of the cost information of the system damage caused by potential intrusion and candidate responses.
Read moreFeature Selection Models Based on Hybrid Firefly Algorithm with Mutation Operator for Network Intrusion Detection
Accurate intrusion detection is necessary to preserve network security. However, developing efficient intrusion detection system is a complex problem due to the nonlinear nature of the intrusion attempts, the unpredictable behaviour of network traffic, and the large number features in the problem space. Hence, selecting the most effective and discriminating feature is highly important. Additionally, eliminating irrelevant features can improve the detection accuracy as well as reduce the learning time of machine learning algorithms. However, feature reduction is an NPhard problem. Therefore, several metaheuristics have been employed to determine the most effective feature subset within reasonable time. In this paper, two intrusion detection models are built based on a modified version of the firefly algorithm to achieve the feature selection task. The first and, the second models have been used for binary and multiclass classification, respectively. The modified firefly algorithm employed a mutation operation to avoid trapping into local optima through enhancing the exploration capabilities of the original firefly. The significance of the selected features is evaluated using a Naïve Bayes classifier over a benchmark standard dataset, which contains different types of attacks. The obtained results revealed the superiority of the modified firefly algorithm against the original firefly algorithm in terms of the classification accuracy and the number of selected features under different scenarios. Additionally, the results assured the superiority of the proposed intrusion detection system against other recently proposed systems in both binary classification and multi-classification scenarios. The proposed system has 96.51% and 96.942% detection accuracy in binary classification and multi-classification, respectively. Moreover, the proposed system reduced the number of attributes from 41 to 9 for binary classification and to 10 for multi-classification.
Read more